Protecting capability indication in ue initiated visited public land mobile network (vplmn) slice-based steering of roaming (sor)
Abstract
Techniques are described to perform network relay security. Multiple methods and an apparatus are proposed to protect the sensitive communication information of users in network communication environment. This application proposes a mechanism for protecting roaming UE capability indication in UE initiated slice-based SoR from attacks such as bidding down attacks. An example communication method includes generating, by a communication device, a request information message that includes a request information to be encrypted by a key, wherein the key is selected from a plurality of key pairs known to the first network node and the communication device, wherein a portion of the request information is transparent to a second network node; and transmitting, from the communication device, the request message to a first network node through the second network node, wherein the request message comprises a key identifier and a user identifier.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A communication method, comprising:
generating, by a communication device, a request information message that includes a request information to be encrypted by a key,
wherein the key is selected from a plurality of key pairs known to a first network node and the communication device,
wherein a portion of the request information is transparent to a second network node; and
transmitting, from the communication device, the request information message to the first network node through the second network node,
wherein the request information message comprises a key identifier and a user identifier.
2 . The method of claim 1 , wherein the communication device and the second network node are affiliated with a same network.
3 . The method of claim 1 , wherein the communication device and the first network node are affiliated with different networks.
4 . The method of claim 1 , wherein each key pair of the plurality of key pairs comprises a public key and a private key.
5 . The method of claim 1 , wherein the key identifier indicates a specific key pair of the plurality of keys pairs.
6 . The method of claim 1 , wherein the user identifier includes subscription permanent identifier (SUPI).
7 . The method of claim 1 , wherein each key pair of the plurality of key pairs comprises a Home Network Public Key and a Home Network Private Key.
8 . The method of claim 1 , wherein the key is a Home Network Public Key.
9 . The method of claim 1 , wherein the first and second network nodes each comprise an access and mobility management function (AMF) device or a Unified Data Management (UDM) device.
10 . A communication method, comprising:
receiving, by a first network node, a first request message that includes a key identifier and a user identifier, wherein the user identifier is associated with a communication device; decrypting, by the first network node, the first request message using a key identified by the key identifier,
wherein the key is selected from a plurality of key pairs known to the first network node and the communication device; and
determining, by the first network node in response to the receiving and the decrypting, to selectively send one of: (a) a response message to a second network node, or (b) a second request message to a third network node, based on a decision rule.
11 . The method of claim 10 , wherein the decision rule comprises:
deciding whether the communication device is authenticated based on the user identifier; checking a capacity information of the communication device when the communication device is authenticated; and in response to deciding when the communication device is not authenticated, send the response message to the second network node, wherein the response message includes a cause of a rejection.
12 . The method of claim 10 , wherein the first network node and the third network node are affiliated with a same network.
13 . The method of claim 10 , wherein the key is a Home Network Private Key.
14 . The method of claim 10 , wherein the first, second, and third network nodes each comprise an access and mobility management function (AMF) device, a Unified Data Management (UDM) device, or a steering of roaming application function (SOR AF).
15 . A communication method, comprising:
generating, by a first network node, a response message that includes a response information encrypted by a key,
wherein the key is selected from a plurality of key pairs known to the first network node and a communication device; and
transmitting, from the first network node, the response message that includes a key identifier to the communication device through a second network node,
wherein a portion of the response information is transparent to the second network node.
16 . The method of claim 15 , wherein the key is a Home Network Public Key.
17 . A communication method, comprising:
receiving, by a communication device, an information message comprising a key identifier,
wherein the information message is transmitted from a first network node to the communication device through a second network node,
wherein the information message is encrypted, and part of the information message is transparent to the second network node; and
decrypting, by the communication device, the information message using a key indicated by the key identifier,
wherein the key is selected from a plurality of key pairs known to the first network node and the communication device.
18 . The method of claim 17 , wherein the key is a Home Network Private Key.Join the waitlist — get patent alerts
Track US2025056214A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.